PHP-FusionÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-05-22Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-12099£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬£¬£¬£¬£¬CVSS·ÖÖµ£º8.8
Ó°Ïì°æ±¾
PHP-Fusion 9.03.00
Îó²î¸ÅÊö
ÔÚphp fusion 9.03.00ÖУ¬£¬£¬£¬£¬edit_profile.phpÔÊÐíÔ¶³Ì¾ÓÉÉí·ÝÑéÖ¤µÄÓû§Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ÓÉÓÚincludes/dynamics/includes/form_fileinput.phpºÍincludes/classes/phpfusion/installer/lib/core.settings.incÔÚÉÏ´«avatarʱ´ú¹ýʧ´¦Öóͷ£ÁË¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
EXP£ºhttps://www.exploit-db.com/exploits/46839¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://github.com/php-fusion/PHP-Fusion/commit/943432028b9e674433bb3f2a128b2477134110e6¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.pentest.com.tr/exploits/PHP-Fusion-9-03-00-Edit-Profile-Remote-
Code-Execution.html
https://www.exploit-db.com/exploits/46839